feat(deploy): pull published image on netcup instead of building

compose.netcup.yaml now references ${LIBRENOTES_IMAGE} with pull_policy: always
and resets the base build context. .env.netcup.example documents the new
LIBRENOTES_IMAGE key (default git.librete.ch/public/librenotes:main, pin to
immutable tag for prod). Rollback: edit .env LIBRENOTES_IMAGE + up -d.
This commit is contained in:
2026-04-29 02:00:15 +02:00
parent 7ba37a5bb3
commit cd932d4d7b
2 changed files with 19 additions and 9 deletions
+13 -8
View File
@@ -1,15 +1,19 @@
# compose.netcup.yaml — overlay for the netcup VPS.
#
# Use:
# docker compose -f docker-compose.yml -f compose.netcup.yaml up -d --build
# docker compose -f compose.yaml -f compose.netcup.yaml pull
# docker compose -f compose.yaml -f compose.netcup.yaml up -d
#
# Differences from base docker-compose.yml:
# Differences from base compose.yaml:
# - Pulls a published image (no build context on the host)
# - No host port binding (caddy edge handles ingress)
# - Joins external `edge` network so caddy reaches it as `librenotes:8080`
# - Pulls config from .env (LIBRENOTES_BASE_URL, JWT_SECRET, SMTP_*)
# - Pulls config from .env (LIBRENOTES_BASE_URL, JWT_SECRET, SMTP_*, IMAGE)
# - Uses bind-mounted /data + /var/lib/librenotes so backups can rsync host paths
#
# Inputs (env or .env file on netcup):
# LIBRENOTES_IMAGE e.g. git.librete.ch/public/librenotes:main
# or pinned tag git.librete.ch/public/librenotes:v0.1.0
# LIBRENOTES_BASE_URL https://ln.cloud.librete.ch
# LIBRENOTES_JWT_SECRET `openssl rand -base64 48`
# LIBRENOTES_SMTP_HOST SMTP relay host
@@ -17,14 +21,15 @@
# LIBRENOTES_SMTP_USER SMTP user
# LIBRENOTES_SMTP_PASS SMTP password
# LIBRENOTES_SMTP_FROM no-reply@librete.ch (envelope sender)
#
# Rollback: edit LIBRENOTES_IMAGE in /srv/librenotes/.env to a prior
# tag, then `docker compose ... pull && docker compose ... up -d`.
services:
librenotes:
build:
context: .
args:
VERSION: netcup
image: librenotes:netcup
build: !reset null
image: ${LIBRENOTES_IMAGE}
pull_policy: always
restart: always
ports: !reset []
environment: